Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Fedora 44 vim Vulnerabilities Leading to Arbitrary Code Execution Risks

fedora
Calendar Grey April 25, 2026
Dist Fedora Esm H88
Critical security updates for Fedora 44 vim affect versions 9.2.280 and address multiple serious threats.
patchlevel 280 Security fix for CVE-2026-34714, CVE-2026-35177, CVE-2026-34982

Summary

VIM (VIsual editor iMproved) is an updated and improved version of the

vi editor. Vi was the first real screen-based editor for UNIX, and is

still very popular. VIM improves on vi by adding new features:

multiple windows, multi-level undo, block highlighting and more.

Update Information:

patchlevel 280 Security fix for CVE-2026-34714, CVE-2026-35177, CVE-2026-34982

Change Log

* Thu Apr 2 2026 Zdenek Dohnal - 2:9.2.280-1 - patchlevel 280 * Tue Mar 31 2026 Zdenek Dohnal - 2:9.2.272-1 - patchlevel 272

References


[ 1 ] Bug #2453139 - CVE-2026-34714 vim: Vim: Arbitrary code execution via crafted file https://bugzilla.redhat.com/show_bug.cgi?id=2453139 [ 2 ] Bug #2455400 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass https://bugzilla.redhat.com/show_bug.cgi?id=2455400 [ 3 ] Bug #2455542 - CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass https://bugzilla.redhat.com/show_bug.cgi?id=2455542

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-251d74645b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: vim
Product: Fedora 44
Version: 9.2.280
Release: 1.fc44
Summary: The VIM editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here